MALICIOUS — HIGH
729281coinbase[.]com
The domain 729281coinbase.com was registered through NameSilo, LLC on December 24, 2025 and is currently listed as offline.
- VirusTotal
- 4/93
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
729281coinbase.com — Контент недоступний (HTTP 502). Уособлення бренду: Coinbase; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 4/93 (ChainPatrol, Fortinet, Seclookup, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
The domain 729281coinbase.com was registered through NameSilo, LLC on December 24, 2025 and is currently listed as offline. Technical resolution shows the domain pointing to IP address 89.125.209.62, which is hosted in the Netherlands under AS212477 owned by RoyaleHosting BV. The authoritative nameservers are emely.ns.cloudflare.com and yoxall.ns.cloudflare.com, indicating the use of Cloudflare DNS services but no TLS certificate is presented for the site, leaving the connection unencrypted. The page title returned by the HTTP response is the generic string "Loading...", and the site lacks any SSL indicator, which is consistent with a rapidly deployed malicious landing page.
Gridinsoft assigns a trust score of 0 out of 100, reflecting a complete lack of reputation. VirusTotal analysis records four detections out of ninety‑three scanning engines, confirming that multiple security products have flagged the domain as malicious. The domain is also present on a single external security blocklist and has been blocked by the PhishDestroy mitigation service. The threat classification is a brand impersonation targeting Coinbase, specifically identified as a crypto‑related scam.
While the exact payload or credential‑harvesting mechanisms have not been publicly disclosed, the convergence of registrar data, hosting location, absence of encryption, low trust score, and multiple vendor detections provides strong evidence of malicious intent. Defenders should continue to block the domain at network perimeter devices, update DNS sinkhole lists, and monitor for any residual traffic from the associated IP range. Incident response teams should also consider correlating logs for attempts to contact this domain with user reports of unauthorized Coinbase activity, and advise users to verify any unsolicited communications that reference Coinbase credentials or crypto transactions.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.